squad-review

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and its local git/GitHub usage is consistent with code review, but it combines untrusted PR content with six parallel subagents granted full tool access. That makes the main risk prompt-injection and overbroad execution scope, not malware or credential theft.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
May 10, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/nicknisi%2Fclaude-plugins%2Fsquad-review%2F@f792cb77372e709219f71424b33049436258de66